Files
plane/pnpm-lock.yaml
sriram veeraghanta a8e53b6ac7 chore(deps): resolve open Dependabot security alerts (#9456)
Bumps three dependencies flagged by Dependabot, closing all 7 open alerts:

- axios 1.16.0 -> 1.18.1 (catalog), closing 5 alerts:
  GHSA-gcfj-64vw-6mp9 (high, inherited proxy after interceptor config clone),
  GHSA-hcpx-6fm6-wx23, GHSA-mwf2-3pr3-8698, GHSA-f4gw-2p7v-4548,
  GHSA-xj6q-8x83-jv6g. Dependabot proposed 1.18.0; 1.18.1 is a pure bugfix
  release on top of it that also fixes runtime crashes and AxiosError
  circular-serialisation, so it is used instead. Supersedes PR #9447.

- brace-expansion 5.0.6 -> 5.0.7 (override), closing GHSA-3jxr-9vmj-r5cp
  (high, DoS via exponential-time expansion of consecutive {} groups).

- morgan -> 1.11.0 (new override), closing GHSA-4vj7-5mj6-jm8m (log forging
  via unneutralized control characters in :remote-user). Pulled in
  transitively by @react-router/serve.

Verified: check:types 28/28, check:lint 16/16, build 16/16.
2026-07-22 00:26:18 +05:30

606 KiB